Use-After-Free Vulnerability in Mozilla Firefox and Thunderbird Products
CVE-2025-1012
Key Information:
- Vendor
Mozilla
- Vendor
- CVE Published:
- 4 February 2025
What is CVE-2025-1012?
A race condition during concurrent delazification in Mozilla Firefox and Thunderbird can result in a use-after-free scenario. This flaw occurs when specific versions of these products process certain memory operations simultaneously, leading to unpredictable behavior and potential exploitation. Users of Firefox versions earlier than 135 and specific versions of Firefox ESR and Thunderbird should be aware of this vulnerability and consider updating to secure versions available to mitigate possible risks.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Firefox < 135
Firefox ESR < 115.20
Firefox ESR < 128.7
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved